My Website Security and Users
Website security is extremely important for anyone who owns or manages a website. When you create a website you are responsible for not only protecting your own information but also the information of the people who visit and interact with your website. Hackers, malware, spam and other security threats can cause your website to crash, steal information or create privacy and security concerns. Even if you have a small website or blog you should still be taking steps to make sure it is secure.
There are many different ways that you can secure your website. One of the most important is having an SSL certificate. An SSL certificate encrypts information that is being shared between the website and the person visiting it. It also gives you HTTPS instead of HTTP and lets visitors know that their connection to your website is secure. For this assignment I activated the SSL certificate through IONOS and used an SSL checker to make sure that it was valid, trusted and working correctly.
Another important way to secure your website is keeping WordPress, themes and plug ins updated. Like I learned in the previous lesson, it is important to make sure that your plugins are coming from trusted sources and are still being regularly updated. Old or abandoned plug ins can create security concerns and if you are no longer using a plugin, there really isn’t a reason to keep it installed on your website.
Security plug ins are another way to add additional protection to your website. For this assignment I installed Wordfence, WP Activity Log, Login LockDown and Really Simple Security. Each of these provides a different type of security for my website. Wordfence can help protect the website from malware and other attacks, WP Activity Log keeps a record of activity happening on the website and Login LockDown helps protect against repeated login attempts. Really Simple Security also works with the SSL and other security settings on the website. I think it is important to have multiple layers of security instead of relying on just one thing to protect your entire website.
Website Users and Roles
User roles are also an important part of website security. Not everyone who works on a website needs to have access to everything. WordPress has different user roles that allows you to control what people can do based on what they actually need access to. Giving everyone Administrator access would create an unnecessary security risk.
For About A Native, I would be the Administrator because I am the website owner and need access to all of the website settings, users, plug ins and content. If I ever had someone helping me manage the entire website I could also use an Editor. An Editor can manage and publish content, including content from other users, without needing all of the access that an Administrator has.
An Author would be useful if I had someone who regularly wrote their own blogs for About A Native. They would be able to create, edit and publish their own posts but would not be able to manage everyone else’s content. A Contributor would make sense for someone who may occasionally write something for the website. They can write and edit their own posts but cannot publish them, which would allow me or an Editor to review the post before it goes live.
Lastly, a Subscriber would be someone who does not need to create or manage content. They have very limited access to the website and can mainly manage their own profile. This could be used for regular visitors or readers if I ever added a reason for people to create accounts on About A Native.
I think having these different roles is important because it gives people the access they need without giving them access to parts of the website they have no reason to be in. If I eventually had multiple people working on About A Native, I would rather assign their role based on what they are actually doing instead of making everyone an Administrator.